Reflected Cross-Site Scripting Vulnerability in TranslatePress Plugin by WordPress
CVE-2026-17505

6.1MEDIUM

What is CVE-2026-17505?

The TranslatePress plugin for WordPress is susceptible to a Reflected Cross-Site Scripting vulnerability due to improper handling of the 's' parameter. In versions up to and including 3.2.5, the translate_page() function replaces specific internal markers with unescaped angle brackets, enabling attackers to inject arbitrary scripts. This flaw allows unauthenticated users to execute harmful web scripts on affected pages, potentially compromising user interactions if a victim clicks on a manipulated link.

Affected Version(s)

TranslatePress – Translate Multilingual sites with AI Translation 0 <= 3.2.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

momopon1415
.